IBM has disclosed a CVSS 9.8 out-of-bounds write flaw in AIX 7.2/7.3 and PowerVM VIOS 4.1 that could let an unauthenticated remote attacker execute arbitrary code.
What Is It
CVE-2026-16840 is an out-of-bounds write (CWE-787) affecting IBM AIX and IBM PowerVM VIOS. Per IBM's advisory, the flaw "could allow a remote attacker to execute arbitrary code." The CVE was published by IBM PSIRT on 2026-08-19 and currently carries NVD status "Received," meaning the record has not yet completed NVD analysis.
Why It Matters
The vendor-assigned CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability factor is maximally favorable to an attacker: network attack vector, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability; an exploitability subscore of 3.9 out of 3.9 and an impact subscore of 5.9.
Memory-corruption bugs of this class on Unix platforms typically execute in privileged context, and VIOS in particular sits underneath virtualized partitions, making it a high-value target in Power environments.
No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation and no federally mandated remediation deadline at this time.
What's Vulnerable
- IBM AIX 7.2 (including 7.2.0)
- IBM AIX 7.3 (including 7.3.0)
- IBM PowerVM VIOS 4.1 (including 4.1.0)
No other products, versions, or configurations are listed in the supplied data.
Patch Status
IBM has published a support advisory at node 7283858 covering this issue. The supplied NVD record does not enumerate specific fix levels, ifixes, or APAR identifiers, so administrators should consult the IBM advisory directly to determine the applicable patch level for their AIX or VIOS release.
Given a remote, unauthenticated, no-interaction code execution path with a 9.8 score, treat this as priority patching for any internet-reachable or laterally-reachable AIX and VIOS hosts. No workarounds or mitigations are documented in the supplied source material.
Sources
- NVD, CVE-2026-16840: https://nvd.nist.gov/vuln/detail/CVE-2026-16840
- IBM Support Advisory (PSIRT): https://www.ibm.com/support/pages/node/7283858